Skip to content
Rota Nacional

Cyber ·

Apache MINA SSHD: authentication policy flaw

A notice published on September 29, 2026 reports that Apache MINA SSHD servers using multi-factor authentication may bypass a requirement for different public keys. The issue has a CVSS 3.1 score of 8.1, rated high.

The notice, automatically translated from a post on the oss-sec feed, describes CVE-2026-93994 in the Java library Apache MINA SSHD, used for client-side and server-side SSH. It affects servers configured with multiple authentication schemes that require different public keys.

According to the text, the issue can bypass that policy. The notice calls the severity important and gives a CVSS 3.1 score of 8.1, with high confidentiality and integrity impact and no availability impact. The stated vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N.

The affected versions listed are Apache MINA SSHD earlier than 2.20.0 and version 3.0.0-M1 through versions earlier than 3.0.0-M6. Check which version is in use and plan an upgrade to a version not listed as affected; then test that the authentication policy requires the intended distinct keys. The supplied excerpt does not explain the flaw's mechanism or provide other remediation steps.

To verify the notice, consult the original post on the oss-sec feed and compare it with the Apache MINA SSHD project's advisory. Confirm versions and upgrade guidance against official sources before acting; the supplied content is an automatic translation and may omit details.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free